Author Topic: Win32:DH fp?  (Read 12441 times)

0 Members and 1 Guest are viewing this topic.

Offline nightshade

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 702
Re: Win32:DH fp?
« Reply #15 on: February 23, 2017, 10:58:21 PM »
I did a quick scan tonight and had to cancel it at 38 percent as it was taking forever, however when it stopped after cancelling it brought up this file virus Win32:DH-A1 named as Updatedownloader.exe it was found in C:\Windows\System32\Codecs

I've put it in the virus chest, should I restore it?

The file properties show the category as Infected files.
« Last Edit: February 23, 2017, 11:13:36 PM by nightshade »
Free avast.
Product version 22.4.6011
Windows 7 32bit
Version 6.1 build 7601 service pack 1

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Win32:DH fp?
« Reply #16 on: February 24, 2017, 12:19:05 AM »
Quote
I've put it in the virus chest, should I restore it?
You can always check file(s) at virustotal and find out



Offline nightshade

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 702
Re: Win32:DH fp?
« Reply #17 on: February 24, 2017, 09:14:50 AM »
Quote
I've put it in the virus chest, should I restore it?
You can always check file(s) at virustotal and find out

Would I not need to restore it first to send them the file?
Free avast.
Product version 22.4.6011
Windows 7 32bit
Version 6.1 build 7601 service pack 1

Offline nightshade

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 702
Re: Win32:DH fp?
« Reply #18 on: February 24, 2017, 09:59:57 AM »
Just tested the file with virustotal and it appears to be a safe file after all, so thanks for the heads up on virustotal.
Free avast.
Product version 22.4.6011
Windows 7 32bit
Version 6.1 build 7601 service pack 1

REDACTED

  • Guest
Re: Win32:DH fp?
« Reply #19 on: March 05, 2017, 11:31:42 AM »
Got hit with the win32:DH-1 tonight.  SYMPTOMS: 50 percent increase of RAM, causing pc to run slow. Could NOT: open apps, run end task, scan with Avast or Malwarebytes. Skd boot scan but sys would not Shut down.  ACTION:  disconnect Ethernet, Hard shut down. Cold book to Safe Mode.  Still couldn't scan. Reboot thinking I'd try a restore point.  On Normal boot the boot scan ran finding 3 Win32:DH-A1 High Threats. Avast Action set to fix auto (repair or delete if can't repair.  All 3 are in Chest.  System running smoothly. 

REDACTED

  • Guest
Re: Win32:DH fp?
« Reply #20 on: March 05, 2017, 03:58:14 PM »
I did a full computer scan, and Avast came up with the file C:/ProgramData\MalwareBytes\MalwareBytes'Anti-Malware\mbam-setup.exe|>[app]\Chameleon\Windows\windows.exe, identifying the virus as Win32:DH-4. I chose each of the actions, but Avast didn't appear to do anything with the file, and I get the message Error: Access Denied. I then ran a Folder Scan for the specific file and I get the same file coming up as virus, but a different version? Win32:DH-1. When I look in the Warnings tab of this folder scan, there's a list of files, all related to Wild Tangent, sequentially 001.jpg, etc., Error: File is a Decompression Bomb. The list continues, other Wild Tangent files, with a new Error: Archive is Password Protected.

I know Wild Tangent is game software. I don't use it, have never used it, and what's the relationship to mbam-setup? No action I take through Avast does anything, and I did do the 2 scans, full & Program Data. I checked the Virus Chest. There are no files in there, although I did attempt to place files in Chest, along with the other actions.

I see in some of the above topics that this could be a false positive? I hope so, but I can't imagine it is with these types of error messages?

Thank you for your help - I've been having serious recent issues with accounts being hacked, etc...and really need to get to the bottom of whatever's happening. Whether it's related to this situation, I have no way of knowing. I'm hoping you can tell me if it might have anything to do with this virus catch.

Could I simply uninstall Wild Tangent? I believe it came bundled with computer, which I received from a friend. HP Desktop, Windows 10, and I do not believe he would have installed Wild Tangent games. He's not computer savvy enough to install any program like that.

I see you've suggested folks upload files to virustotal, but who the heck knows which file I'd check - there are so many that seem to be associated with this!

Thank you again,
Pamela

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Win32:DH fp?
« Reply #21 on: March 05, 2017, 04:07:54 PM »
WildTangent is a Redmond, Washington based game network, privately held in the United States that powers game services for several PC manufacturers including Dell and HP